logo

Marimo Pre-Auth RCE via Unauthenticated WebSocket Terminal (CVE-2026-39987)

ID: e3b36734-8ad9-54dc-90af-5af241987260

STIX ID: report--e3b36734-8ad9-54dc-90af-5af241987260

Feed Name: Resecurity

Threat Score
90/100

Date Published: 2026-04-16

Date Updated: 2026-07-27

...
...

A critical pre-auth remote code execution vulnerability (CVE-2026-39987) exists in Marimo's /terminal/ws WebSocket endpoint due to missing authentication before spawning a PTY shell, allowing unauthenticated attackers to obtain full interactive system shells; the report includes code-level analysis, a Python PoC exploit, a Nuclei template for detection, impact assessment, and remediation guidance (upgrade to 0.23.0+, restrict exposure, and harden deployments).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.